
The Securities and Exchange Board of India (SEBI) has released an urgent warning for listed businesses and regulated institutions regarding a sophisticated financial fraud known as the “Boss Scam”.
Triggered by intelligence from the Indian Cyber Crime Coordination Centre (I4C), the alert highlights a rising trend where digital thieves impersonate Chief Executives and Managing Directors to manipulate employees into transferring corporate funds.
Cybercriminals are leveraging advanced technology rather than traditional phishing methods, utilising two distinct operational strategies:
Artificial Intelligence Exploitation
Fraudsters deploy sophisticated AI voice cloning and deepfake video streams during virtual calls to perfectly mimic C-suite executives. To enforce compliance, subordinates are frequently instructed to keep these sudden fund transfers strictly confidential, under the false pretence of protecting sensitive, market-moving data.
Session Token Hijacking
Attackers transmit corrupted .zip files containing stealthy Trojan malware. When an unsuspecting financial officer opens the file on a desktop, the payload steals active WhatsApp Web session tokens. This grants the attacker full control over the employee’s messaging account to order fraudulent payouts. Alternatively, if full device access is achieved, the malware alters contact names directly, changing the fraudster’s number to show up as the CEO’s name.
To mitigate these risks, SEBI advises corporate teams to implement strict verbal confirmation protocols before acting on text-based financial orders. Organizations should also routinely log out of inactive web messaging sessions, block unverified attachments, and instantly report breaches to the national cybercrime hotline.